Agent skill

OAuth Account Setup

by spinabot in spinabot/brigade

Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

MITAuto-check passedBackend & APIs

Install OAuth Account Setup

skills CLI
$ npx skills add spinabot/brigade --skill oauth-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spinabot/brigade oauth-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spinabot/brigade.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oauth-setup .claude/skills/oauth-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oauth-setup
GitHub stars
11k
Token cost
~878 tokens
SKILL.md length
347 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

  • Works in 2 steps: Use a Desktop-app OAuth client, not a… → Use the real scope. Gmail send is…
  • Connecting a Gmail or Google API account to the agent
  • SKILL.md covers The two mistakes to avoid…, Flow and Using a connected account…
  • Reaches googleapis.com and gmail.com

What it does

The skill tells the agent to use the oauth_authorize tool rather than building a listener by hand. The tool opens a one-time loopback listener on a free port, captures the authorization code and seals the tokens in the credential store. It also names two pitfalls: use a Desktop-app OAuth client, which accepts any loopback redirect without registration, instead of a Web client that triggers redirect_uri_mismatch, and use the real scope URLs, such as the Gmail send scope under googleapis.com.

The flow asks the operator to create a Desktop-app client with the Gmail API enabled and the consent screen in testing, then paste the client ID and secret. The agent starts the flow, with offline access and a consent prompt so a refresh token is issued, sends the returned authorization link to click, and waits for the redirect, repeating the wait if the status is still pending.

Afterwards the tokens cannot be read from files or the database, by design. The agent lists connected accounts with a status action that shows provider, email, scopes and expiry without secrets, and asks for a token action to get a live access token, refreshed automatically, before calling the API, for example to send mail.

When your agent uses it

  • Connecting a Gmail or Google API account to the agent
  • Fixing a redirect_uri_mismatch error during OAuth
  • Checking which OAuth accounts are connected and when they expire

Example prompts

  • “Connect my Gmail account so you can send mail on my behalf.”
  • “I keep getting redirect_uri_mismatch when authorizing Google; help me fix it.”
  • “Show which OAuth accounts are connected and when their tokens expire.”

Requirements

  • A runtime that provides the oauth_authorize tool and a credential store
  • A Google Cloud Desktop-app OAuth client with the Gmail API enabled

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Use a Desktop-app OAuth client, not a Web client. In Google Cloud Console → Credentials → Create OAuth client ID → Application type…
  2. Use the real scope. Gmail send is https://www.googleapis.com/auth/gmail.send (NOT https://gmail.com/..., which doesn't exist). Add openid…

What it can do on your machine

Read from SKILL.md and the folder at commit 4c2a18f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com
    • gmail.com
    • gmail.googleapis.com
    • accounts.google.com
    • oauth2.googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

OAuth Account Setup loads about 878 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 347 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~878

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spinabot/brigade at commit 4c2a18f, republished under its MIT licence (© spinabot). 347 words, ~878 tokens.

Download SKILL.mdSave it as .claude/skills/oauth-setup/SKILL.md (or your agent's skills folder).
name
oauth-setup
description
Connect an OAuth 2.0 service (Gmail, Google APIs, etc.) using the built-in oauth_authorize tool — get a click-to-authorize link, auto-capture the code, and seal the tokens. Use whenever the operator asks to connect Gmail / a Google API / any OAuth account.

OAuth setup

Use the oauth_authorize tool — NEVER hand-roll an http listener in bash. It opens a one-shot loopback listener on a free port (no EADDRINUSE, no port juggling), captures the code, and seals the tokens into the credential store.

The two mistakes to avoid (they cost a whole session once)

  1. Use a Desktop-app OAuth client, not a Web client. In Google Cloud Console → Credentials → Create OAuth client ID → Application type: Desktop app. Desktop clients accept ANY http://127.0.0.1:<port> loopback redirect with no redirect-URI registration. A Web client requires the exact redirect URI pre-registered, which is what causes redirect_uri_mismatch.
  2. Use the real scope. Gmail send is https://www.googleapis.com/auth/gmail.send (NOT https://gmail.com/..., which doesn't exist). Add openid https://www.googleapis.com/auth/userinfo.email if you want the account address auto-filled.

Flow

  1. Ask the operator to create a Desktop-app OAuth client (Gmail API enabled, consent screen in Testing with themselves as a test user) and paste the client id + secret.
  2. Start the flow:
    oauth_authorize({
      action: "start",
      provider: "google-gmail",
      authorizationEndpoint: "https://accounts.google.com/o/oauth2/v2/auth",
      tokenEndpoint: "https://oauth2.googleapis.com/token",
      userInfoEndpoint: "https://www.googleapis.com/oauth2/v3/userinfo",
      clientId: "<id>", clientSecret: "<secret>",
      scopes: ["https://www.googleapis.com/auth/gmail.send", "openid", "https://www.googleapis.com/auth/userinfo.email"],
      extraAuthParams: { access_type: "offline", prompt: "consent" }
    })
    access_type=offline + prompt=consent are required for a refresh token (otherwise re-auth is needed when the access token expires).
  3. Send the operator the returned authUrl to click.
  4. Await the redirect — it exchanges the code and seals the tokens:
    oauth_authorize({ action: "await", flowId: "<flowId from start>" })
    If it returns status pending, the operator hasn't clicked yet — tell them, then call await again.
Show full SKILL.md (137 more words)Show less

Using a connected account (sending mail)

The tokens are sealed in the credential store — you can't read them from a file or the DB, and you shouldn't try. To use a connected account:

  1. Check what's connected: oauth_authorize({ action: "status" }) → lists each account (provider, email, scopes, expiry). No secrets.
  2. Get a usable token: oauth_authorize({ action: "token", provider: "google-gmail" }) → returns accessToken. It auto-refreshes from the sealed refresh token when the old one expired, so you always get a live token. (Pass provider only if more than one account is connected.)
  3. Call the API with it. Gmail send: POST https://gmail.googleapis.com/gmail/v1/users/me/messages/send, header Authorization: Bearer <accessToken>, body { "raw": "<base64url RFC-822 message>" }.

Never cat the credential store, grep for the token, or hand-roll a refresh — action:"token" is the only retrieval path, and it keeps the refresh token + client secret sealed.

© spinabot, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/oauth-setup of spinabot/brigade.

Open the folder on GitHubat commit 4c2a18f

Compare with similar skills

OAuth Account Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

OAuth Account Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
OAuth Account Setup this skillspinabot/brigade11k—~878Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS6179 repos~4.4kAutomated safety check: PassNone

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 9 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from spinabot/brigade

All 11 skills in this repo
  • Canvas Display

    spinabot/brigade

    Shows HTML content such as games, dashboards, visualizations and demos on a connected Brigade node's canvas, using a local canvas host server and a node bridge.

    11k GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Word Document Builder

    spinabot/brigade

    Creates and edits Word documents along four paths of rising capability, from a quick tool to the docx library, an OOXML round-trip and pandoc, then verifies the file.

    11k GitHub stars~2.1k tokensUpdated 4 days ago
    Auto-check passed
  • Writes HTML compositions with a GSAP timeline that the render_video tool turns into deterministic MP4 videos from data, text or layouts.

    11k GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Diagnoses why a Brigade companion app can't pair or connect, by first identifying the real node-to-gateway route and then fixing auth.

    11k GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Brigade PDF Toolkit

    spinabot/brigade

    Creates and edits PDFs in Brigade through four paths: a quick content tool, an edit tool for forms and merging, a pdf-lib script for full control, and HTML-to-PDF for styled layouts.

    11k GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed
  • Share Skills

    spinabot/brigade

    Explains how a skill folder should be laid out and bundled as a tar archive for sharing, with a checklist covering name, description and eligibility keys.

    11k GitHub stars~759 tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about OAuth Account Setup

What does OAuth Account Setup do?

Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage. The skill tells the agent to use the oauth_authorize tool rather than building a listener by hand. The tool opens a one-time loopback listener on a free port, captures the authorization code and seals the tokens in the credential store.

When should I use OAuth Account Setup?

OAuth Account Setup fits situations like: connecting a Gmail or Google API account to the agent; fixing a redirect_uri_mismatch error during OAuth; checking which OAuth accounts are connected and when they expire.

How do I install OAuth Account Setup in Claude Code?

Run `npx skills add spinabot/brigade --skill oauth-setup -a claude-code`. Or copy the skill folder (skills/oauth-setup in spinabot/brigade) into .claude/skills/oauth-setup in your project. Claude Code loads it when a task matches its description.

How do I install OAuth Account Setup in Codex?

Run `npx skills add spinabot/brigade --skill oauth-setup -a codex`. Or copy the skill folder (skills/oauth-setup in spinabot/brigade) into .agents/skills/oauth-setup in your project. Codex loads it when a task matches its description.

Can I use OAuth Account Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spinabot/brigade --skill oauth-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oauth-setup, .gemini/skills/oauth-setup, .github/skills/oauth-setup and .opencode/skills/oauth-setup in your project.

What does OAuth Account Setup need to run?

SKILL.md names no scripts, command-line tools or credentials: OAuth Account Setup is instructions for the agent only. Our summary lists: A runtime that provides the oauth_authorize tool and a credential store; A Google Cloud Desktop-app OAuth client with the Gmail API enabled.

Does OAuth Account Setup access the network?

SKILL.md names 5 domains. In commands or code: googleapis.com, gmail.com, gmail.googleapis.com, accounts.google.com and oauth2.googleapis.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is OAuth Account Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does OAuth Account Setup use?

OAuth Account Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does OAuth Account Setup use?

About 878 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to OAuth Account Setup?

Skills that share tags, products or a category with OAuth Account Setup: Fortify Development (coollabsio/coolify, 63k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains OAuth Account Setup?

spinabot (a GitHub organization) maintains it in spinabot/brigade, which has 11,276 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 3, 2026.

Source: spinabot/brigade on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.